Profiles Configuration and App policy to manage devices

I am trying to create and configure Android Work Managed profile and IOS profile for specific groups. And configure the App Policies for each device type. it should be as follows:-
  1. Group1: Only 1 specific link is allowed & Apps Authorised are (MS Teams,OneDrive, M365 Apps, Camera)
  2. Group2: Only authorized apps are allowed (MS Teams,OneDrive, M365 Apps, Camera)
a) Is there a way to block all URLs and allow only 1 specific URL? Like using domains or '*'?
b) What would be the best practice to allow only the apps suggested above and block everything else?
c) If i set System Update Policy / Installation Policy to Automatic in Profiles, will all devices get updates automatically or should i manually check for device updates from SOTI Console?
d) what would be the best practice to achieve this setup/configuration? for e.g using system update policy, web filter, feature control, application run control..and app policy
2 years ago
SOTI MobiControl
ANSWERS
RC
Raymond Chan Diamond Contributor
2 years ago

For (a), use a secure browser that support URL whitelist and/or kiosk mode 

For (b), use whitelists in application-run-control profile policy

For (c), should be automatic, but possibly with model/mode dependent time delays as stipulated by platform owner or device OEM vendor support pages